Hi, what version of SEE are you using?
Otherwise, it might be worth confirming that the policies are getting to the computers. You can do this using resultant set of policy (see page 13 of the Policy Admin documentation). I'm not sure how it applies that particular decrypt policy otherwise - have you tried doing gpupdate /force and rebooting a couple of times?